Hacker News new | past | comments | ask | show | jobs | submit login

This seems to be allowing unsafe script injection from ONLY certain whitelisted urls, presumably excluding the url globs required for the ads. Haven't tested it, and not sure the full extent of pshc's sibling response either.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: